Details

Updated gimp packages that fix three security issues are now available forRed Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having moderatesecurity impact. Common Vulnerability Scoring System (CVSS) base scores,which give detailed severity ratings, are available for each vulnerabilityfrom the CVE links in the References section.

An integer overflow flaw, leading to a heap-based buffer overflow, wasfound in the GIMP's GIF image format plug-in. An attacker could create aspecially-crafted GIF image file that, when opened, could cause the GIFplug-in to crash or, potentially, execute arbitrary code with theprivileges of the user running the GIMP. (CVE-2012-3481)

A heap-based buffer overflow flaw was found in the Lempel-Ziv-Welch (LZW)decompression algorithm implementation used by the GIMP's GIF image formatplug-in. An attacker could create a specially-crafted GIF image file that,when opened, could cause the GIF plug-in to crash or, potentially, executearbitrary code with the privileges of the user running the GIMP.(CVE-2011-2896)

A heap-based buffer overflow flaw was found in the GIMP's KiSS CEL fileformat plug-in. An attacker could create a specially-crafted KiSS palettefile that, when opened, could cause the CEL plug-in to crash or,potentially, execute arbitrary code with the privileges of the user runningthe GIMP. (CVE-2012-3403)

Red Hat would like to thank Matthias Weckbecker of the SUSE Security Teamfor reporting the CVE-2012-3481 issue.

Users of the GIMP are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. The GIMP must berestarted for the update to take effect.

Solution

Before applying this update, make sure all previously-released erratarelevant to your system have been applied.